Just a warning, a lot of these SSDs "cheat" by using compression. I bought the best drive that I could find for my macbook pro - OCZ Vertex 3 Max IOPS, and was rather disappointed to find out that the posted speeds are based on benchmarks with compressible data. The reason this is an issue is because if you use disk encryption like you should be doing, encrypted data is not compressible. As a result, my speeds are 1/3rd to 1/2 of that which is advertised, and it was not worth the extra money.
> if you use disk encryption like you should be doing
I've never found that I had a really good reason to encrypt a drive yet, I'm kind of surprised to see a suggestion that this is the way things are done.
The OP specifically mentioned a MPB, a laptop, which are pretty easy and high value targets for theft. If my laptop was stolen, I would be relieved to know that my personal data was safe.
There are additional reasons for full disk encryption too, like ensuring that important system files have not been tampered with. Whether or not you want to go that far depends entirely on your level of paranoia.
For a home desktop, the cost/benefit may be a bit different, because the computer is exposed to less places and people. As with many things in security, you would need to calculate what is an acceptable risk to you versus the cost of mitigating that risk.
If you ever have to wipe an SSD the wear-leveling will totally mess with your wipe process. It is always best practice to just do full disk encryption on SSDs, even if you aren't taking it out of the house/office.
If you work in financial,medical, government or with any employee data (ie, corporate HR systems) and use a laptop, it's often a good idea for the laptop-issuing organization to mandate full disk encryption to prevent unintentional sensitive data loss (an inside job will bypass this protection).
In addition to doing data recovery for people (sensitive documents, photos, etc.), I have a few clients I do work for and I'm exposed to client lists, password files, software license keys, etc.. If my home-office machine were ever stolen, I never need to worry since I use full-disk crypto.
I approach full disk encryption and how we "should be doing" it the same way I approach brushing my teeth 3x a day and flossing 1x a day. Yea, I should, but I brush my teeth 2.5x a day and floss 1x a week instead, and it's worked O.K. so far.
Compressed data reduced your IOPS. Is the drive slower at handle compressed data, or is your OS the bottleneck because its compressing all data before sending to hardware? I appreciate that you might not care exactly where the problem is, but it'd be good to know if SSDs suck just for realtime-encrypted file systems, or for any non-compressible data such as MP3s, JPEGs etc.
Also, how does your encrypted-fs affect HDD performance?
Don't get me wrong, an SSD was definitely worth it over an HDD. Despite being slower than the advertised speeds by a lot, it is still far better than before. I'm just saying that paying extra for a "tier 1 performance" SSD may not be worth the money over a mid-range one if that extra performance is gained by the controller doing aggressive compression (as the sandforce-based SSDs apparently do).
The reason that I know that this is not just encryption overhead is because when asked about lower performance being seen by users who were not encrypting, OCZ staff confirmed on their forums that benchmarks not using compressible data will see lower numbers.
I googled a bit and saw that it's widely documented that sandforce are compressing right in the controller, and this allows it to physically do less reading/writing, which artificially inflates the data transfer speed.
Attempting to compress encrypted data has no effect on the size of the data whatsoever, so tests doing that are more reflective of their actual performance.
Comments
Just a warning, a lot of these SSDs "cheat" by using compression. I bought the best drive that I could find for my macbook pro - OCZ Vertex 3 Max IOPS, and was rather disappointed to find out that the posted speeds are based on benchmarks with compressible data. The reason this is an issue is because if you use disk encryption like you should be doing, encrypted data is not compressible. As a result, my speeds are 1/3rd to 1/2 of that which is advertised, and it was not worth the extra money.
> if you use disk encryption like you should be doing
I've never found that I had a really good reason to encrypt a drive yet, I'm kind of surprised to see a suggestion that this is the way things are done.
Why should you be encrypting your disks?
The OP specifically mentioned a MPB, a laptop, which are pretty easy and high value targets for theft. If my laptop was stolen, I would be relieved to know that my personal data was safe.
There are additional reasons for full disk encryption too, like ensuring that important system files have not been tampered with. Whether or not you want to go that far depends entirely on your level of paranoia.
For a home desktop, the cost/benefit may be a bit different, because the computer is exposed to less places and people. As with many things in security, you would need to calculate what is an acceptable risk to you versus the cost of mitigating that risk.
If you ever have to wipe an SSD the wear-leveling will totally mess with your wipe process. It is always best practice to just do full disk encryption on SSDs, even if you aren't taking it out of the house/office.
Edit: Reference https://www.infosecisland.com/blogview/13722-SSDs-and-the-Im...
If you work in financial,medical, government or with any employee data (ie, corporate HR systems) and use a laptop, it's often a good idea for the laptop-issuing organization to mandate full disk encryption to prevent unintentional sensitive data loss (an inside job will bypass this protection).
Customer data.
In addition to doing data recovery for people (sensitive documents, photos, etc.), I have a few clients I do work for and I'm exposed to client lists, password files, software license keys, etc.. If my home-office machine were ever stolen, I never need to worry since I use full-disk crypto.
I approach full disk encryption and how we "should be doing" it the same way I approach brushing my teeth 3x a day and flossing 1x a day. Yea, I should, but I brush my teeth 2.5x a day and floss 1x a week instead, and it's worked O.K. so far.
Russian roulette is not a big deal. I've shot this revolver at my forehead 5 times now, and it's worked ok so far.
Perhaps he has data that he doesn't want people looking at if it's lost or stolen.
So which drive should I pick if I want to stay away from the ones that "cheat"?
Compressed data reduced your IOPS. Is the drive slower at handle compressed data, or is your OS the bottleneck because its compressing all data before sending to hardware? I appreciate that you might not care exactly where the problem is, but it'd be good to know if SSDs suck just for realtime-encrypted file systems, or for any non-compressible data such as MP3s, JPEGs etc.
Also, how does your encrypted-fs affect HDD performance?
Don't get me wrong, an SSD was definitely worth it over an HDD. Despite being slower than the advertised speeds by a lot, it is still far better than before. I'm just saying that paying extra for a "tier 1 performance" SSD may not be worth the money over a mid-range one if that extra performance is gained by the controller doing aggressive compression (as the sandforce-based SSDs apparently do).
The reason that I know that this is not just encryption overhead is because when asked about lower performance being seen by users who were not encrypting, OCZ staff confirmed on their forums that benchmarks not using compressible data will see lower numbers.
I googled a bit and saw that it's widely documented that sandforce are compressing right in the controller, and this allows it to physically do less reading/writing, which artificially inflates the data transfer speed.
Attempting to compress encrypted data has no effect on the size of the data whatsoever, so tests doing that are more reflective of their actual performance.